XP reboots randomly, boot menu changed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by psyence4, Dec 12, 2007.

  1. psyence4

    psyence4 Private E-2

    Hi, my computer recently reboots at least once a day, and each time it reboots the System Configuration Utility will pop up informing me that i have made changes to my system settings. It's currently set on Selective Startup (I disabled a lot of programs to make it load up faster) and it always reboots when I'm away from the computer (usually in the wee hours of the morning)

    Also, my administrator rights have been toggled mysteriously even though my account has full right (i.e. when I try to update Firefox or Thunderbird sometimes it tells me that I need administrator privileges).

    I also cannot boot up into safe mode via the F8 method; pressing F8 now takes me to a Windows 98 startup menu instead of the XP one with the "Last Known Good Configuration" and "Safe Mode" options. Selecting the "Safe Mode" option now takes me to a command prompt instead, and I did not dare to try rebooting directly into safe mode as I was afraid that malware would prevent me from booting normally again.

    I've done all the scans, nothing serious was found, only cookies (or so the software says) and oddly AVG anti-spyware refuses to generate a report despite my changing the settings. So I've only posted the MGtools and Combofix logs. Thanks!
     

    Attached Files:

    Last edited: Dec 12, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Then reboot!

    After reboot, run MSconfig and select Normal Startup mode as was requested in the READ ME. Then reboot one more time.

    After doing the above, please download the current version of MGtools.exe to C:\ like you previously did. It was just updated. Then run MGtools.exe which will create a new C:\MGlogs.zip file. Please attach this new log file.
    .​
     
    Last edited: Dec 12, 2007
  3. psyence4

    psyence4 Private E-2

    Hi, attached is the latest version of MGlogs. I tried to change the System Configuration settings to the Normal startup but it told me that I didn't have Administrator rights. But somehow it managed to start up with everything on the next reboot.
     

    Attached Files:

  4. psyence4

    psyence4 Private E-2

    Sorry, forgot to use the new version of MGtools; here is the updates mglogs.zip
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you ran the old version of MGtools inbetween then you have to start over again with the whole message right from the fixME.reg patch thru to getting the new log. So tell me what you did.
     
  6. psyence4

    psyence4 Private E-2

    Ok I ran the old version in between, so I redid everything

    1. ran fixMe.reg
    2. rebooted
    3. ran MGtools.exe
    4. rebooted cos my internet wasn't working
    5. here is the log file
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please Disable Spybot's TeaTimer as was requested in the READ ME
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    NOTE: In the READ & RUN ME we stringly recommend that you uninstall MessengerPlus3. It is the root cause of thousands of PC being infected. Latest versions of even been associated with Vundo infections. We don't trust it even if you don't install the third part malware that is bundled with it.

    We also ask you to uninstall Viewpoint Media Player in the READ ME. Please uninstall it now.

    Also at the very start of the READ ME we indicate that you must not use multiple antivirus programs. You appear to have ignored this. You have AVG 7, NOD32, and ZoneAlarm Security Suite installed and I see remnants of an incomplete uninstall of Norton. Please uninstall all but one antivirus program now and also uninstall the below from Norton:
    • LiveReg (Symantec Corporation)
    • LiveUpdate 3.0 (Symantec Corporation)
    • Norton WMI Update
    In addition to the above we also stated that you must only use one software firewall. You have Sygate and ZoneAlarm installed. So it you have not uninstall ZoneAlarm from above, you must uninstall Sygate now.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    With all of the complications from not doing the above steps properly in the READ ME, we will now need a new log but make sure you address all of the above issues first before doing the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
  8. psyence4

    psyence4 Private E-2

    I've done the required steps and here is the new log. Incidentally I don't have MessengerPlus3 on my machine.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! Look in add/remove programs because I see this Messenger Plus! 3
    It is definitely in your registry and it is showing as loading at startup and it is running: C:\Program Files\MessengerPlus! 3\MsgPlus.exe

    Did you forget to do the below? I still see it:
    You logs are basically clean! You just have a load of junk being disable by MSconfig that we asked you not to use in the READ ME.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Then reboot!
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.

    Then reboot!
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created

    Make sure you tell me how things are working now!

    Are things better now that we uninstall all the duplicate software???
     
  10. psyence4

    psyence4 Private E-2

    Yeah it seems to be working better now. However, msconfig still complains when I try to change the startup menu. Also, I think my F8 menu is still spoilt; but I edited boot.ini to allow me to boot up in safe mode. Thanks for the help though! Also, I ran the disable messenger thing but it didn't work.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    This may be more of an issue to discuss in the Software Forum. It could be a permissions issue with certain registry keys. Try booting in safe mode but log into the account name administrator, does it have the same problem running msconfig.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds